flash

HSBC ... Wire Transfer Copy.exe

Status: finished
Submission Time: 25.11.2021 18:48:24
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • exe
  • Formbook
  • HSBC

Details

  • Analysis ID:
    528773
  • API (Web) ID:
    896295
  • Analysis Started:
    25.11.2021 18:55:52
  • Analysis Finished:
    25.11.2021 19:06:13
  • MD5:
    99b154970d15748d1df9025f675ecc76
  • SHA1:
    75503611daf18643a401c2020ae9e045111b7f1f
  • SHA256:
    13af03cd2db9c68bc397fd81f101287df005f27bc806737ffad390324a068d4c
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
11/65

malicious
18/45

IPs

IP Country Detection
34.102.136.180
United States
172.217.168.83
United States

Domains

Name IP Detection
www.catproductreviews.com
0.0.0.0
www.piramsgprodiet.store
0.0.0.0
www.gramaltinrafineri.com
0.0.0.0
Click to see the 3 hidden entries
ghs.google.com
172.217.168.83
gramaltinrafineri.com
34.102.136.180
catproductreviews.com
34.102.136.180

URLs

Name Detection
www.atlantiscompania.com/m4n8/
http://www.gramaltinrafineri.com/m4n8/?5jblCF=6FC/YAdxArGDbOG0ZU8ranLB3olQ8/HIU17UMwKJ54PfoS0z6/xA4+VoDBKhLnDEQ6+k&l0G=-Zrd9J1pqHLdHPo
http://www.catproductreviews.com/m4n8/?l0G=-Zrd9J1pqHLdHPo&5jblCF=fqwcloTwW+H6Usea82LuZckhsM6vXxH+7LRp9WPFBQLwjEJmVheIZ7PCXY+dS9vifeb6
Click to see the 2 hidden entries
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
https://www.piramsgprodiet.store/m4n8/?l0G=-Zrd9J1pqHLdHPo&5jblCF=tUrd37IHNwUNrKy1BA5QR6EUYG6BNH

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\HSBC ... Wire Transfer Copy.exe.log
ASCII text, with CRLF line terminators
#